Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-104075 2026-10-08

TVU Networks Receiver/Transceiver Authentication Bypass (CVE-2026-104075)

"TVU Networks Receiver/Transceiver devices running firmware before version 7.9 have a critical authentication bypass that lets remote, unauthenticated attackers take full administrative control of the device's web…"

TVU Networks Receiver/Transceiver devices running firmware before version 7.9 have a critical authentication bypass that lets remote, unauthenticated attackers take full administrative control of the device's web management interface.

What Is It

CVE-2026-104075 is an authentication bypass in the web management login endpoint, POST /tvu/Login, on TVU Networks Receiver/Transceiver devices. If the UserName parameter is empty or missing, the device issues a valid administrative session cookie no matter what password is supplied.

The login form has client-side JavaScript validation, but it does not stop the attack. An attacker can send a crafted HTTP request straight to the endpoint and skip the browser-side checks entirely. The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel).

Why It Matters

VulnCheck, the CVE's source, rates the flaw 9.8 CRITICAL under CVSS v3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS v4.0. The vectors describe a flaw that is:

A successful attacker gets full administrative control of the device's web management interface.

This CVE has no CISA Known Exploited Vulnerabilities (KEV) entry in the supplied data, so active exploitation is not confirmed by KEV. The NVD record status is "Deferred."

What's Vulnerable

The NVD record lists no specific CPEs.

Patch Status

The affected range ends before firmware version 7.9, so 7.9 and later are not affected. Operators should identify TVU Receiver/Transceiver devices running firmware older than 7.9 and upgrade them to 7.9 or later. The vendor advisory linked below has full remediation details.

Because this CVE is not in KEV, the supplied data includes no CISA-mandated required action or due date.

Sources